> ## Documentation Index
> Fetch the complete documentation index at: https://docs.chatsailer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Effective write policy for this workspace

> Mirror of the internal ``GET /crm/capabilities``, minus the per-user
grant layer — tokens are gated by scopes instead. The company policy
(ADR 2026-07-29-001) binds every actor, tokens included.



## OpenAPI

````yaml /api-reference/openapi.json get /v1/capabilities
openapi: 3.1.0
info:
  description: >-
    The Sailer REST API for CRM, conversations, and campaigns.


    **Authentication.** Send a scoped token as `Authorization: Bearer
    sk_live_...`.

    Tokens are workspace-scoped; the workspace is implied by the token, so no

    tenant header is needed. During early access, tokens are issued by Sailer on

    request — contact your Sailer representative.


    **Pagination.** Collections return `{data, meta, links}`. Follow
    `links.next`

    until it is `null`; treat the cursor as opaque.


    **Errors.** Every non-2xx response is `{"error": {...}}` with a stable
    `code`.

    Quote `error.request_id` when contacting support.


    **Custom fields.** Workspace-defined fields appear under `custom_fields`,
    keyed

    by `field_key`. Read a record to see which keys a workspace uses; a
    dedicated

    field-discovery endpoint is not part of this release.
  title: Sailer API
  version: 1.0.0
servers:
  - url: https://api.chatsailer.com
security:
  - SailerApiToken: []
tags:
  - description: Token introspection and workspace capabilities.
    name: Meta
  - description: >-
      People you talk to. Called *leads* in older Sailer surfaces; `contact` is
      the current name.
    name: Contacts
  - description: Companies that contacts belong to (B2B accounts).
    name: Organizations
  - description: Opportunities moving through a pipeline.
    name: Deals
  - description: Pipelines and their stages.
    name: Pipelines
  - description: Field definitions, including custom fields.
    name: Fields
  - description: Free-text annotations on CRM records.
    name: Notes
  - description: Scheduled and logged CRM activities.
    name: Activities
  - description: Per-entity label catalogs.
    name: Tags
  - description: Message threads with contacts, across every channel.
    name: Conversations
  - description: Outbound campaigns and their participants.
    name: Campaigns
paths:
  /v1/capabilities:
    get:
      tags:
        - Meta
      summary: Effective write policy for this workspace
      description: |-
        Mirror of the internal ``GET /crm/capabilities``, minus the per-user
        grant layer — tokens are gated by scopes instead. The company policy
        (ADR 2026-07-29-001) binds every actor, tokens included.
      operationId: get_capabilities
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CapabilitiesResponse'
          description: Successful Response
      security:
        - SailerApiToken: []
components:
  schemas:
    CapabilitiesResponse:
      properties:
        entities:
          description: >-
            Per-entity write policy for this workspace. A false value here means
            the workspace has disabled the write (typically because an external
            CRM is the system of record), not that the token lacks scope.
          items:
            $ref: '#/components/schemas/EntityCapability'
          title: Entities
          type: array
      required:
        - entities
      title: CapabilitiesResponse
      type: object
    EntityCapability:
      properties:
        can_create:
          title: Can Create
          type: boolean
        can_delete:
          title: Can Delete
          type: boolean
        can_update:
          title: Can Update
          type: boolean
        entity:
          title: Entity
          type: string
      required:
        - entity
        - can_create
        - can_update
        - can_delete
      title: EntityCapability
      type: object
  securitySchemes:
    SailerApiToken:
      description: >-
        A workspace API token. Create one in Settings → API. Send it as
        `Authorization: Bearer sk_live_...`.
      scheme: bearer
      type: http

````